ISO 27701:2025 — What Actually Changed, and What It Means for Your Certificate
A privacy lead at an Indian IT services firm called us in November, fairly pleased with himself. His organisation had held ISO 27701 since 2022, the certificate was on the website, and enterprise questionnaires were going out with it attached. Then a German client's vendor-risk team asked a question he had not planned for: which edition, and what is your transition plan? He had not registered that the standard had been rewritten a month earlier. The certificate was still valid. The answer to the question was not.
ISO/IEC 27701 was republished on 14 October 2025, and it is not a cosmetic refresh. The standard has been rebuilt from an add-on into a management system that stands on its own. If you hold the 2019 certificate, or you were about to start a privacy programme, the shape of the work has changed. This is what changed, what it means in practice, and what you should be doing between now and the deadline.
The headline change: 27701 no longer sits on top of ISO 27001
The 2019 edition was explicitly an extension. You could not certify to it alone — you needed an ISO 27001 ISMS underneath, and 27701 supplemented those clauses with privacy requirements. That single design decision shaped every 27701 project for six years: privacy teams had to wait for, or drag along, an information security certification they may not have needed for its own sake.
The 2025 edition removes that dependency. It is a standalone management system standard, retitled "Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance", with its own complete set of requirements. You can now certify a Privacy Information Management System (PIMS) without first certifying an ISMS.
Be careful how you read that, though. Standalone does not mean lighter. Because the standard can no longer borrow ISO 27001's controls by reference, it now carries a set of information security controls of its own. You are not escaping security work — you are choosing whether to run it inside a PIMS or alongside an ISMS. For most organisations that already hold ISO 27001, the combined route remains the sensible one, and it is still supported.
The new structure, clause by clause
The 2025 edition adopts the Harmonized Structure — the common skeleton used by ISO 27001:2022, ISO 42001:2023 for AI, ISO 9001 and the rest. If you have implemented any modern ISO management system, Clauses 4 to 10 will feel familiar.
| Clause | What it covers | What to watch for |
|---|---|---|
| 4 — Context | Scope, interested parties, PII in scope | Now includes climate-change consideration, per the 2024 amendment applied across ISO management standards |
| 5 — Leadership | Policy, roles, accountability | Privacy accountability must be assigned explicitly, not inherited from the ISMS |
| 6 — Planning | Risk and objectives | The big one: a privacy risk assessment focused on risk to individuals, distinct from security risk to the organisation |
| 7 — Support | Competence, awareness, documented information | Your PIMS documentation must be self-contained if you certify standalone |
| 8 — Operation | Running the PIMS | Operational privacy processes — DPIAs, rights handling, breach response |
| 9 — Performance evaluation | Monitoring, internal audit, management review | Internal audit programme must cover Annex A controls in their new structure |
| 10 — Improvement | Nonconformity, corrective action | Standard HS wording |
Clause 6 deserves a pause. In many 2019-era programmes, privacy risk was folded into the information security risk register and scored the same way — likelihood times impact, impact measured in harm to the business. The 2025 edition asks for a privacy risk assessment oriented to risk to the PII principal: the actual person whose data you hold. Those two assessments produce different answers. A dataset that is low-risk to your balance sheet can be high-risk to the individuals in it. If your current register cannot show that distinction, this is your largest gap, and it is a methodology change rather than a documentation change.
Controls moved into Annex A — and there are 78 of them
In 2019 the controls were embedded in the body of the standard, in clauses that supplemented ISO 27001 and ISO 27002. In 2025 they sit where an auditor expects to find them: a structured Annex A, split by the role you play.
| Annex A table | Applies to | Controls |
|---|---|---|
| A.1 | PII controllers — you decide why and how personal data is processed | 31 |
| A.2 | PII processors — you process on a controller's instructions | 18 |
| A.3 | Information security controls, applicable to both roles | 29 |
| Total | — | 78 |
Implementation guidance has been separated out into Annex B, so the requirement and the advice on meeting it are no longer interleaved. In practice this makes the Statement of Applicability far cleaner to write and much easier for an auditor to test against.
One honest caveat, because you will see this claimed both ways. Some certification bodies describe the 2025 controls as a restructuring of what already existed rather than a set of genuinely new obligations; others highlight strengthened treatment of areas such as automated decision-making and de-identification. Both readings are defensible, and the difference matters less than it sounds: whichever is true, you still have to re-map every control you claimed in 2019 onto the new Annex A and rebuild your SoA. Do not let a "nothing is really new" summary talk you out of the mapping exercise.
The annexes are where the transition work actually lives
Most of the practical value in the 2025 edition sits behind Annex A, and it is worth knowing what is there before you commission a gap analysis — several of these annexes replace work you would otherwise pay someone to do.
| Annex | Contents | Why it matters to you |
|---|---|---|
| A | 78 controls across controller, processor and security tables | The basis of your new Statement of Applicability |
| B | Implementation guidance, separated from the requirements | Read alongside A when deciding how far to go on each control |
| C | Mapping to ISO/IEC 29100 privacy principles | Useful when your policy framework is written around privacy principles |
| D | Mapping to the GDPR | Evidence reuse if you serve EU markets — one control set, two conversations |
| E | Mapping to ISO/IEC 27018 and ISO/IEC 29151 | Relevant if you are a cloud processor already aligned to 27018 |
| F | Correspondence between the 2019 and 2025 editions, both directions | Your transition starting point — do not rebuild the mapping by hand |
Annex F is informative rather than normative, so an auditor will not test you against it. That is not a reason to ignore it: Table F.1 maps 2025 controls back to 2019 and Table F.2 maps forward, which between them turn a re-mapping exercise that consumes weeks into one that consumes days.
Dates you actually need in the calendar
| Date | What happens |
|---|---|
| 14 October 2025 | ISO/IEC 27701:2025 published |
| 31 October 2026 | Deadline for certification bodies to be accredited to the 2025 edition |
| 31 October 2028 | End of the transition period — ISO/IEC 27701:2019 certificates cease to be valid |
Three years sounds generous. It is the same arithmetic that caught people out on the ISO 27001:2013 to 2022 transition. Your existing certificate stays valid until it expires or the deadline arrives, whichever comes first — so the real constraint is your own certification cycle, not October 2028. If your recertification falls in 2027, that audit is your natural transition point, which means the gap analysis needs to happen in 2026. Working backwards from your next recertification date is the only planning that matters here.
There is also a squeeze worth anticipating. Every 27701-certified organisation in the world is transitioning into the same window, against a finite pool of accredited auditors, and certification bodies themselves only had to be ready by October 2026. Late movers will be competing for audit slots.
If you already hold ISO 27701:2019, here is the work
- Get your recertification date, and work backwards. That date, not the 2028 deadline, sets your timeline.
- Run the mapping using Annex F. The standard ships a correspondence table from the 2019 controls to their 2025 equivalents — start there rather than from a blank sheet.
- Rewrite the Statement of Applicability against the new Annex A structure, split across the controller, processor and security tables. Whether you are a controller, a processor, or both for different processing activities, decide it per activity and document why.
- Rebuild the privacy risk assessment so risk to individuals is assessed distinctly from risk to the organisation. Expect this to be the longest item.
- Decide standalone or combined. If you already hold ISO 27001, combined is usually less work and tells a better story to enterprise buyers. If you do not, standalone is now genuinely available and removes a large dependency.
- Check your PIMS documentation stands on its own if you go standalone — anything that currently cross-references the ISMS needs to be brought inside the PIMS.
- Re-scope your internal audit programme so the new Annex A structure is covered before the transition audit, not during it.
If you are starting privacy from scratch
Start on the 2025 edition. There is no sensible reason to implement a standard that stops being certifiable in 2028, and no credit for having done so.
For Indian organisations there is a second, more practical reason to move now. The Digital Personal Data Protection Act, 2023 imposes obligations — consent, notice, data-principal rights, breach notification, and heavier duties for Significant Data Fiduciaries — that map closely onto what a PIMS makes you build anyway: knowing what personal data you hold, why, on what lawful basis, for how long, and who it goes to. A PIMS does not make you DPDP-compliant on its own, and anyone who tells you otherwise is selling something. But the two share most of their evidence base, and building them together is materially cheaper than building them twice.
The mistake we expect to see most
Treating this as a documentation exercise. The temptation is to renumber the SoA, refresh the policy pack, and present it at the transition audit. That will survive a light touch and fail a competent one, because the two changes with real teeth — a privacy risk assessment oriented to the individual, and a PIMS that genuinely stands alone — are both changes to how you work, not to what you have written down. The organisations that struggle in 2028 will be the ones that mapped the controls and never revisited the risk methodology.
FAQs
Do we still need ISO 27001 to certify to ISO 27701:2025?
No. The 2025 edition is a standalone management system standard and no longer depends on ISO/IEC 27001 or 27002. Combined certification remains available and is usually the more efficient route if you already hold ISO 27001, because the two systems share governance, internal audit and management review.
When do ISO 27701:2019 certificates expire?
The transition period ends on 31 October 2028. Existing certificates remain valid until they expire or that date arrives, whichever is first. In practice your own recertification cycle will force the decision earlier, so plan from your next recertification date.
How many controls are in ISO 27701:2025?
Annex A contains 78 controls: 31 for PII controllers, 18 for PII processors, and 29 information security controls that apply to both. Implementation guidance sits separately in Annex B.
Is the transition just a paperwork update?
No. Two changes require real work: Clause 6 asks for a privacy risk assessment focused on risk to the individual rather than to the organisation, and a standalone PIMS must be self-contained rather than cross-referencing an ISMS. The control mapping is the easy part.
Does ISO 27701 make us compliant with India's DPDP Act?
No single certification makes you DPDP-compliant. DPDP is law and ISO 27701 is a voluntary management standard. That said, they overlap heavily on data inventory, lawful basis, retention, data-principal rights and breach response, so a well-run PIMS supplies much of the evidence a DPDP programme needs — and demonstrates diligence if you are ever asked to show it.
We are a processor, not a controller. Does much change for us?
Yes. Processor obligations now sit in their own Annex A table (18 controls) rather than being scattered through the 2019 text, which makes your scope clearer both to define and to evidence. Many organisations are a controller for some processing and a processor for others, so decide the role activity by activity and record the reasoning.
Where to start
If you hold the 2019 certificate, the first useful hour is spent on two things: your next recertification date, and an honest look at whether your privacy risk register measures harm to people or harm to the business. Those two answers tell you how much time you have and how much of the work is methodology rather than paperwork. Everything else follows from that.
Liked the post? Share on:




Leave A Comment